Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

10 detectors match the current filters. tactic: TA0002 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A TCP stream was created directly in a shell Attackers may create a TCP stream using the shell command line to generate a reverse shell, enabling remote access to the endpoint. Medium Platform Analytics XDR Agent Execution
Analytics BIOC Commonly abused AutoIT script connects to an external domain AutoIT scripts have legitimate uses, but are often abused by malware to execute in a signed process context. Medium Platform Analytics XDR Agent Exfiltration, Execution
Analytics BIOC Kubernetes vulnerability scanner activity A Kubernetes cluster was scanned by a known vulnerability scanner. Medium Platform Analytics XDR Agent Execution, Discovery
Analytics BIOC Possible compromised machine account A Kerberos TGT for machine account has been used and does not match the hostname. Medium Platform Analytics XDR Agent Execution
Analytics BIOC PowerShell suspicious flags Abbreviated flags in PowerShell indicate malicious intent. Medium Platform Analytics XDR Agent Execution
Analytics BIOC Suspicious SearchProtocolHost.exe parent process SearchProtocolHost.exe has been launched from a process that is different from SearchIndexer.exe This may indicate malicious activity (such as malware later being injected to it, or it being used for phantom DLL hijacking). Medium Platform Analytics XDR Agent Execution, Defense Evasion
Analytics BIOC Uncommon AppleScript designed to access credential files was executed via the command line The AppleScript interpreter was executed with a script designed to access credential files such as keychains or SSH keys. Medium Platform Analytics XDR Agent Execution, Credential Access
Analytics BIOC Uncommon DLL-sideloading from a logical CD-ROM (ISO) device A DLL was loaded by an executable from the same folder on a logical CD-ROM device (ISO). Medium Platform Analytics XDR Agent Execution, Defense Evasion, Privilege Escalation
Analytics BIOC Uncommon Service Create/Config The Service Control command (sc.exe) is used to create, start, stop, query, or delete Windows services. Adversaries may attempt to use the command to execute and persist a binary, command, or script. Medium Platform Analytics XDR Agent Execution
Analytics BIOC Unusual process executed by AWS Systems Manager An unusual process was executed by the AWS Systems Manager agent. Adversaries may use the Systems Manager agent to execute malicious commands on an endpoint. Medium Cortex Cloud XDR Agent Execution